stacksmashing / tamarin-firmware

GNU General Public License v3.0
458 stars 54 forks source link

Tamarin Firmware

Tamarin Logo

PICO SDK NOTE

Please build with the Pico-SDK Version 4fe995d0ec984833a7ea9c33bac5c67a53c04178

Newer versions have some USB incompatibility.

Build

mkdir build
cd build
cmake ..
make

Hooking it up

Pinout diagram

With this cable, connect:

Note: The colors might be different for your cable. I recommend checking the pinout using a voltmeter.

Lightning

Another cable was observed to have the following pinout:

If you would like to connect to your device over USB, cut a USB cable and connect its wires like this:

Usage

Tamarin Cable provides three USB endpoints, of which two are serial ports.

Serial port 1 is the control serial port, use it to configure DCSD/JTAG mode.

Serial port 2 is the DCSD port, when Tamarin Cable is in DCSD mode the serial output will be provided here.

OpenOCD

To use Tamarin as a JTAG adapter you need to use our OpenOCD fork that includes support for the Tamarin probe.

To enable JTAG on production iPhones they need to be demoted. For checkm8 vulnerable iPhones this can be done using ipwndfu.

Once the phone is successfully demoted the bonobo configs can be used to connect to the iPhone like so:

openocd -f interface/tamarin.cfg -f t8015.cfg

Known issues

  1. Commands are unavailable in JTAG mode. Workaround: Enter the desired command and then reconnect the device. To reset the device you can also use JTAG.
  2. JTAG is not re-enabled after manual device reset. Workaround: Run the JTAG command again, then reconnect the device (or the Tamarin cable).